Lucene search

K
cveMitreCVE-2006-1761
HistoryApr 13, 2006 - 1:06 a.m.

CVE-2006-1761

2006-04-1301:06:00
mitre
web.nvd.nist.gov
27
cve-2006-1761
cross-site scripting
xss
vulnerability
index.php
remote attackers
web script
html
sanitization
error message
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.011

Percentile

84.5%

Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized in the error message. NOTE: the vector in the shard parameter is not XSS and has been assigned a separate name.

Affected configurations

Nvd
Node
blursoftblur6exMatch0.3.462
VendorProductVersionCPE
blursoftblur6ex0.3.462cpe:2.3:a:blursoft:blur6ex:0.3.462:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.011

Percentile

84.5%

Related for CVE-2006-1761